π§πΎ
lns.bz
2026-10-10 19:37:23
(22 minutes ago)
Too many 404 requests [BY]
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 19:28:19
(31 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.221.115.223 (223.115.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.115.223 (223.115.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:28:12.295775 2026] [security2:error] [pid 29328:tid 29328] [client 35.221.115.223:39520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||smallbizreorg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smallbizreorg.com"] [uri "/z9x8c7v6b5-debug-trigger-smallbizreorg.com"] [unique_id "asqRzAAS-rSuXemaCAZz7wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-10-10 19:27:22
(32 minutes ago)
Web attack/malicious scanning detected
Web App Attack
π―π΅
bokumin.org
2026-10-10 19:23:50
(36 minutes ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg " ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
π³π±
Alt255
2026-10-10 19:21:32
(38 minutes ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.221.115.223 - - [10/Oct/2026:21:21:26 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 301 301 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-10-10 19:20:02
(39 minutes ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π©πͺ
konseptit
2026-10-10 19:18:37
(41 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 35.221.115.223 (JP/Japan/223.115.221.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.221.115.223 (JP/Japan/223.115.221.35.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-10-10 19:10:04
(49 minutes ago)
IP matched detection query Detection of too many failed responses.
Brute-Force
Bad Web Bot
Hacking
πΊπΈ
TPI-Abuse
2026-10-10 18:28:27
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.115.223 (223.115.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.115.223 (223.115.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 14:28:22.546923 2026] [security2:error] [pid 15174:tid 15174] [client 35.221.115.223:39268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||slmd.me|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "slmd.me"] [uri "/rclone.conf"] [unique_id "asqDxmMZg7rDupV8MadY8QAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
conseilgouz
2026-10-10 18:27:37
(1 hour ago)
sle-88 : Bloc AI bots=>/z9x8c7v6b5-debug-trigger-sllabonneetoile.fr(ai.)
Hacking
π³π±
Savvii
2026-10-10 18:11:43
(1 hour ago)
20 attempts against mh-misbehave-ban on joost-pr
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 18:09:50
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.115.223 (223.115.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.115.223 (223.115.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 14:09:47.351398 2026] [security2:error] [pid 28986:tid 28986] [client 35.221.115.223:53864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pages4you.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pages4you.com"] [uri "/z9x8c7v6b5-debug-trigger-pages4you.com"] [unique_id "asp_a9xz3Zzr4zh653nD2wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-10-10 18:09:10
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
Web App Attack
Hacking
π©πͺ
MarkGGN
2026-10-10 17:56:13
(2 hours ago)
Web attack. 35.221.115.223 - - [10/Oct/2026:19:56:12 +0200] "GET /core/.env HTTP/2.0" 444 0 "-" "Moz ...
show more
Web attack. 35.221.115.223 - - [10/Oct/2026:19:56:12 +0200] "GET /core/.env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.221.115.223 - - [10/Oct/2026:19:56:12 +0200] "GET /.git/config HTTP/2.0" 404 705 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
show less
Web App Attack
π©πͺ
rh24
2026-10-10 17:43:57
(2 hours ago)
(badbots) Bad bot user-agent [redacted] from 35.221.115.223 (JP/Japan/223.115.221.35.bc.googleuserco ...
show more
(badbots) Bad bot user-agent [redacted] from 35.221.115.223 (JP/Japan/223.115.221.35.bc.googleusercontent.com)
show less
Hacking